---
id: CVE-2026-23010
title: 'ipv6: Fix use-after-free in inet6_addr_del().'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ipv6: Fix use-after-free in inet6_addr_del().

  syzbot reported use-after-free of inet6_ifaddr in
  inet6_addr_del(). [0]

  The cited commit accidentally moved ipv6_del_add…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= ca97dd10424860a3806ad3a9e26b9dce2901ee0c <
    6e89d60b4f03014f7d412ce64b17a840840d490e
  - >-
    Linux >= 836deb96383ed9c1a411f172954d74b3f74ec6ac <
    9356b69d03d0f50cce91cebdabd33dda023fbd64
  - >-
    Linux >= cb74207ef98317f8874a0b9780bb339c2eb700b0 <
    2684610a9c9c53f262fd864fa5c407e79f304804
  - >-
    Linux >= 00b5b7aab9e422d00d5a9d03d7e0760a76b5d57f <
    8b6dcb565e419846bd521e31d5e1f98e4d0e1179
  - >-
    Linux >= 00b5b7aab9e422d00d5a9d03d7e0760a76b5d57f <
    ddf96c393a33aef4887e2e406c76c2f8cda1419c
  - Linux 851b3bb105c595cc20b8dcc1b4de029061ce2b76
  - Linux >= 6.1.120 < 6.1.162
  - Linux >= 6.6.64 < 6.6.122
  - Linux >= 6.12.2 < 6.12.67
  - Linux >= 6.11.11 < 6.12
  - Linux 6.13
exploitAvailable: true
published: '2026-01-25'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:44:36.446Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-23010'
references:
  - url: 'https://git.kernel.org/stable/c/6e89d60b4f03014f7d412ce64b17a840840d490e'
  - url: 'https://git.kernel.org/stable/c/9356b69d03d0f50cce91cebdabd33dda023fbd64'
  - url: 'https://git.kernel.org/stable/c/2684610a9c9c53f262fd864fa5c407e79f304804'
  - url: 'https://git.kernel.org/stable/c/8b6dcb565e419846bd521e31d5e1f98e4d0e1179'
  - url: 'https://git.kernel.org/stable/c/ddf96c393a33aef4887e2e406c76c2f8cda1419c'
tags:
  - cve.org
  - exploit-available
epss: 0.00203
epssPercentile: 0.09039
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/George0Papasotiriou/CVE-2026-23010-CCSDS-Telecommand-Replay-Without-Sequence-Number
  checkedAt: '2026-09-25T08:20:53.008Z'
ingestedAt: '2026-09-08T15:33:26.994Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ipv6: Fix use-after-free in inet6_addr_del().

syzbot reported use-after-free of inet6_ifaddr in
inet6_addr_del(). [0]

The cited commit accidentally moved ipv6_del_addr() for
mngtmpaddr before reading its ifp->flags for temporary
addresses in inet6_addr_del().

Let's move ipv6_del_addr() down to fix the UAF.

[0]:
BUG: KASAN: slab-use-after-free in inet6_addr_del.constprop.0+0x67a/0x6b0 net/ipv6/addrconf.c:3117
Read of size 4 at addr ffff88807b89c86c by task syz.3.1618/9593

CPU: 0 UID: 0 PID: 9593 Comm: syz.3.1618 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
Call Trace:
 <TASK>
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
 print_address_description mm/kasan/report.c:378 [inline]
 print_report+0xcd/0x630 mm/kasan/report.c:482
 kasan_report+0xe0/0x110 mm/kasan/report.c:595
 inet6_addr_del.constprop.0+0x67a/0x6b0 net/ipv6/addrconf.c:3117
 addrconf_del_ifaddr+0x11e/0x190 net/ipv6/addrconf.c:3181
 inet6_ioctl+0x1e5/0x2b0 net/ipv6/af_inet6.c:582
 sock_do_ioctl+0x118/0x280 net/socket.c:1254
 sock_ioctl+0x227/0x6b0 net/socket.c:1375
 vfs_ioctl fs/ioctl.c:51 [inline]
 __do_sys_ioctl fs/ioctl.c:597 [inline]
 __se_sys_ioctl fs/ioctl.c:583 [inline]
 __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f164cf8f749
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f164de64038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007f164d1e5fa0 RCX: 00007f164cf8f749
RDX: 0000200000000000 RSI: 0000000000008936 RDI: 0000000000000003
RBP: 00007f164d013f91 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f164d1e6038 R14: 00007f164d1e5fa0 R15: 00007ffde15c8288
 </TASK>

Allocated by task 9593:
 kasan_save_stack+0x33/0x60 mm/kasan/common.c:56
 kasan_save_track+0x14/0x30 mm/kasan/common.c:77
 poison_kmalloc_redzone mm/kasan/common.c:397 [inline]
 __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:414
 kmalloc_noprof include/linux/slab.h:957 [inline]
 kzalloc_noprof include/linux/slab.h:1094 [inline]
 ipv6_add_addr+0x4e3/0x2010 net/ipv6/addrconf.c:1120
 inet6_addr_add+0x256/0x9b0 net/ipv6/addrconf.c:3050
 addrconf_add_ifaddr+0x1fc/0x450 net/ipv6/addrconf.c:3160
 inet6_ioctl+0x103/0x2b0 net/ipv6/af_inet6.c:580
 sock_do_ioctl+0x118/0x280 net/socket.c:1254
 sock_ioctl+0x227/0x6b0 net/socket.c:1375
 vfs_ioctl fs/ioctl.c:51 [inline]
 __do_sys_ioctl fs/ioctl.c:597 [inline]
 __se_sys_ioctl fs/ioctl.c:583 [inline]
 __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f

Freed by task 6099:
 kasan_save_stack+0x33/0x60 mm/kasan/common.c:56
 kasan_save_track+0x14/0x30 mm/kasan/common.c:77
 kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:584
 poison_slab_object mm/kasan/common.c:252 [inline]
 __kasan_slab_free+0x5f/0x80 mm/kasan/common.c:284
 kasan_slab_free include/linux/kasan.h:234 [inline]
 slab_free_hook mm/slub.c:2540 [inline]
 slab_free_freelist_hook mm/slub.c:2569 [inline]
 slab_free_bulk mm/slub.c:6696 [inline]
 kmem_cache_free_bulk mm/slub.c:7383 [inline]
 kmem_cache_free_bulk+0x2bf/0x680 mm/slub.c:7362
 kfree_bulk include/linux/slab.h:830 [inline]
 kvfree_rcu_bulk+0x1b7/0x1e0 mm/slab_common.c:1523
 kvfree_rcu_drain_ready mm/slab_common.c:1728 [inline]
 kfree_rcu_monitor+0x1d0/0x2f0 mm/slab_common.c:1801
 process_one_work+0x9ba/0x1b20 kernel/workqueue.c:3257
 process_scheduled_works kernel/workqu
---truncated---

## Affected

- `Linux >= ca97dd10424860a3806ad3a9e26b9dce2901ee0c < 6e89d60b4f03014f7d412ce64b17a840840d490e`
- `Linux >= 836deb96383ed9c1a411f172954d74b3f74ec6ac < 9356b69d03d0f50cce91cebdabd33dda023fbd64`
- `Linux >= cb74207ef98317f8874a0b9780bb339c2eb700b0 < 2684610a9c9c53f262fd864fa5c407e79f304804`
- `Linux >= 00b5b7aab9e422d00d5a9d03d7e0760a76b5d57f < 8b6dcb565e419846bd521e31d5e1f98e4d0e1179`
- `Linux >= 00b5b7aab9e422d00d5a9d03d7e0760a76b5d57f < ddf96c393a33aef4887e2e406c76c2f8cda1419c`
- `Linux 851b3bb105c595cc20b8dcc1b4de029061ce2b76`
- `Linux >= 6.1.120 < 6.1.162`
- `Linux >= 6.6.64 < 6.6.122`
- `Linux >= 6.12.2 < 6.12.67`
- `Linux >= 6.11.11 < 6.12`
- `Linux 6.13`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
